Description
An attacker may achieve arbitrary code execution on a target system by uploading a malicious device driver package, bypassing driver verification mechanisms, and triggering the execution of
attacker-controlled code. User interaction is required.
Published: 2026-09-11
Score: 8.3 High
EPSS: n/a
KEV: No
Impact: Remote code execution via unverified driver upload
Action: Patch Immediately
AI Analysis

Impact

The vulnerability allows an attacker to obtain arbitrary code execution on a system running the Sentio Creator Device Manager extension by uploading a malicious device driver package. The driver bypasses normal verification controls, enabling attacker‑controlled code to run with the privileges of the local user. Because arbitrary code runs under the context of the process that loads the driver, the impact includes full compromise for the affected system.

Affected Systems

Affected products are SICK AG's Sentio Creator Extension 'Device Manager'. The issue is mitigated by upgrading to version 1.4.1 of the extension; no other version ranges are provided, so all earlier releases are considered vulnerable until the upgrade is applied.

Risk and Exploitability

The CVSS v3.1 score of 8.3 classifies the flaw as high severity. No EPSS score is available, and the vulnerability is not currently listed in the CISA KEV catalog, indicating no widespread exploitation is reported. Exploitation requires user interaction to supply the malicious driver package, so the attack vector is likely local or requires the attacker to persuade a user to load the driver. Given the high severity and potential for system compromise, the risk to environments that rely on the Device Manager is significant.

Generated by OpenCVE AI on September 11, 2026 at 09:20 UTC.

Remediation

Vendor Solution

Users are strongly recommended to upgrade the Device Manager extension for Sentio Creator to version 1.4.1.


OpenCVE Recommended Actions

  • Upgrade the Sentio Creator Device Manager extension to version 1.4.1.
  • If the upgrade cannot be applied immediately, disable or restrict the ability to upload custom driver packages, limiting installations to signed drivers only.
  • Monitor system logs for driver‑loading events and flag unexpected or unauthorized driver installations.

Generated by OpenCVE AI on September 11, 2026 at 09:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 11 Sep 2026 08:30:00 +0000

Type Values Removed Values Added
Description An attacker may achieve arbitrary code execution on a target system by uploading a malicious device driver package, bypassing driver verification mechanisms, and triggering the execution of attacker-controlled code. User interaction is required.
Title CVE-2026-80469
Weaknesses CWE-347
References
Metrics cvssV3_1

{'score': 8.3, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: SICK AG

Published:

Updated: 2026-09-11T08:27:39.772Z

Reserved: 2026-08-26T12:59:50.751Z

Link: CVE-2026-80469

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-11T09:17:20.833

Modified: 2026-09-11T09:17:20.833

Link: CVE-2026-80469

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-11T09:30:07Z

Weaknesses
  • CWE-347

    Improper Verification of Cryptographic Signature